Privacy Policy
Last updated June 20, 2026
Swarm is a multi-tenant software-engineering automation platform operated by Myrik (“Myrik”, “we”, “us”). This policy explains what data we process when your organization uses Swarm, why, and the choices you have. Data is scoped to your organization; members of one organization cannot access another organization’s data.
Data we collect
- Account — name, email, and a salted hash of your password (passwords are never stored in clear text). For Google sign-in, your Google profile email and name.
- Organization settings & credentials — connection secrets you choose to add: GitHub tokens, model-provider API keys (Anthropic, OpenAI, Google Gemini, AWS Bedrock, others), Jira credentials, and log-source tokens. Stored encrypted at rest and scoped to your organization.
- Repository & run content — when a run executes, the targeted repositories are cloned to ephemeral, isolated compute, processed, and the resulting branches are pushed to your Git remote. Prompts, code, logs, and any files you attach are processed to perform the run.
- Monitoring data — if you connect a log/trace source, Swarm fetches recent log samples to detect and triage incidents; representative samples are included in analysis.
- Operational records — run metadata, token/cost usage, and an audit log of security-relevant actions.
How we use it
- Operate the service: plan, implement, test, review, and ship the work you request.
- Detect, triage, and (when you enable it) remediate incidents from your connected sources.
- Enforce cost caps, quotas, and tenant isolation, and maintain security audit trails.
- Diagnose problems and improve reliability.
We do not sell your data, and we do not use your private code or prompts to train our own models.
Model providers & sub-processors
To perform runs and triage, relevant content (prompts, code excerpts, log samples) is sent to the model provider your organization configures — Anthropic by default, or others you select. Hosting and storage run on AWS. See the Sub-processors page for the current list.
Storage, location & retention
- Primary data is stored in AWS (Mumbai, ap-south-1) using managed, encryption-at-rest services.
- Cloned repositories and worktrees live only on ephemeral run compute and are not retained after the run.
- Attachments and run artifacts are retained for the operating life of the run record; you can request deletion.
- Log-sample/monitoring history is short-lived (rolling window) and ages out automatically.
Security
Access is organization-scoped, credentials are encrypted at rest, traffic is encrypted in transit (TLS), and optional TOTP MFA and Google SSO are available. See the Security page for detail.
Your choices & rights
- Add or remove connected credentials and repositories at any time in Settings.
- Disconnect monitoring sources to stop log collection.
- Request access to, export of, or deletion of your organization’s data via the contact below.
Contact
Privacy questions or data requests: privacy@myrik.in.